|
171
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parameter in all versions up to, and including, 2.2.9 due to insufficient input sanit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-3878
|
2026-04-16 13:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
6.2 |
MEDIUM
Local
|
-
|
-
|
jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-33947
|
2026-04-16 13:17 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
7.5 |
HIGH
Network
|
-
|
-
|
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.
New
|
CWE-93
CRLF Injection
|
CVE-2026-6351
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
9.8 |
CRITICAL
Network
|
-
|
-
|
MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6350
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
- |
|
-
|
-
|
The
iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
New
|
CWE-78
OS Command
|
CVE-2026-6349
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
8.8 |
HIGH
Local
|
-
|
-
|
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machin…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-6348
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-3885
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
- |
|
-
|
-
|
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a T…
New
|
CWE-367 CWE-494
Time-of-check Time-of-use (TOCTOU) Race Condition Download of Code Without Integrity Check
|
CVE-2026-3428
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
- |
|
-
|
-
|
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources duri…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-1880
|
2026-04-16 12:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
4.9 |
MEDIUM
Local
|
-
|
-
|
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-40962
|
2026-04-16 11:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|